Does Iowa Conversational AI Services Act (SF 2417) require Data Governance?

Iowa • enacted

Yes — 1 provision

Requirements at a glance

This regulation imposes 3 specific requirements for Data Governance across 1 provision:

Minor Privacy and Parental Control Tools #

Obligation:
Data Governance
enacted
Effective:
Jul 1, 2027
Risk tier:
limited-risk
Scope:
Operators of conversational AI services with minor account holders; the guardian-facing duty is unconditional for account holders under thirteen years of age and risk-calibrated for older minors (§ 554J.2(5)(b)-(c))
upcoming
The statute requires the tools to exist but says nothing about what they must control, so the compliance floor is a settings surface rather than a defined set of parental permissions. The § 554J.2(5)(c) "as appropriate based on relevant risks" formulation is the only risk-proportionate duty in the chapter and is left entirely to the Attorney General's chapter 17A rulemaking to give content.

Requirements

RequirementDetails
Minor self-service controlsOffer tools for minor account holders to manage their own privacy and account settings (§ 554J.2(5)(a))
Guardian controls under 13Offer tools for the parent or guardian of a minor account holder under thirteen years of age to manage the minor's privacy and account settings (§ 554J.2(5)(b))
Risk-calibrated guardian controlsOffer tools for the parent or guardian of a minor account holder to manage the minor's privacy and account settings as appropriate based on relevant risks (§ 554J.2(5)(c))

Penalties

ViolationFine
Any violation of chapter 554JInjunction plus the greater of actual damages or a civil penalty of $1,000 per violation, capped at $500,000 per operator (§ 554J.6(1))
EnforcementAttorney General only; no private right of action (§ 554J.6(2), § 554J.6(4))
View full regulation View obligation Obligation matrix